节点文献
基于Windows的进程监控系统设计与实现
The Design and Application Process Monitoring System Based on Windows
【Author】 Chang Jun,Zong Rong,Yu Jiang,Liu Yinshan (School of Information Science and Engineering,Yunnan University,Kunming,650091,China)
【机构】 云南大学 信息学院;
【摘要】 针对目前恶意进程的检测方法漏检率和错检率高,功能单一,没有提供与其它安全事件关联的接口和方法的问题,提出了基于调用线程调度链表例程的隐藏进程检测算法,结合误用检测和异步检测的进程混合检测算法,并实现了一个原型系统——Sanship Windows。通过基于FU_RootKit工具软件的编程接口开发了木马攻击实例,进行了模拟攻击实验,结果显示系统能准确地检测出攻击行为,验证了算法在主机系统中的可行性,为主机系统的安全防御提供了有效的解决方案。
【Abstract】 In order to solve the problems of high omission ratio and miss ratio,too simple function and absence of interfaces with security event correlation,we,through call thread scheduling routines list,propose a hidden process detection algorithm which combines anomaly detection with misuse detection and with which the prototype system Sanship Windows is developed.Simulate attack tests have been made,based on FU_RootKit API,to prove that Sanship Windows can detect attacker correctly,to confirm its feasibility in host system and to provide host security with a significant solution.
【Key words】 process monitoring; hidden process detection; thread scheduling list; RootKit;
- 【会议录名称】 2010通信理论与技术新发展——第十五届全国青年通信学术会议论文集(下册)
- 【会议名称】2010通信理论与技术新发展——第十五届全国青年通信学术会议
- 【会议时间】2010-08-06
- 【会议地点】中国云南昆明
- 【分类号】TP393.08
- 【主办单位】中国通信学会